Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
The Finance Base
AI security

Sweet Security Raises $75M Series B to Expand Cloud and AI Security

Sweet Security raised $75 million to expand its runtime cloud-security platform into AI security. Here’s what the launch covers, what remains unverified and what buyers should test.

By TheFinanceBase Team 6 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sweet Security announced a $75 million Series B on November 12, 2025, led by Evolution Equity Partners, with Munich Re Ventures, Glilot Capital Partners and Key1 Capital participating. The Tel Aviv-based company said it would use the funding for international expansion and product development, while adding AI-security capabilities to its runtime-focused cloud security platform. Sweet calls the product the “first unified runtime CNAPP” for cloud and AI security; that “first” claim is the company’s positioning, not an independently established market fact.

What Sweet Security announced

The company’s November 12, 2025 announcement describes a $75 million Series B led by Evolution Equity Partners, alongside Munich Re Ventures, Glilot Capital Partners and Key1 Capital. Sweet said the round brings its total funding to $120 million. A same-day CEO blog post instead says $125 million, so the company’s public materials conflict on cumulative funding.

Sweet was founded by Dror Kashti, Eyal Fisher and Orel Ben Ishay. The announcement did not disclose a company valuation, revenue, customer-contract values or the round’s structure. It reported that proceeds would support global expansion and product innovation.

What “runtime CNAPP” means

A cloud-native application protection platform (CNAPP) is a broad category of tools for securing cloud applications and infrastructure. Depending on the product, that can include cloud posture and vulnerability management, workload protection, identity risk, application security, and detection and response. Sweet emphasizes the live-production layer: what applications, workloads, identities and infrastructure are doing while they run, and how related events may form an attack sequence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Sweet describes its platform as combining cloud detection and response (CDR), application detection and response (ADR) and cloud workload protection (CWPP). Its runtime CNAPP product page promotes an eBPF-based sensor, real-time detection and response, vulnerability and posture management, identity-threat protection and API security. These are vendor-described capabilities; the materials cited here do not provide independent performance testing.

Runtime visibility complements rather than replaces pre-deployment safeguards. A runtime product can show behavior that actually occurs, but it does not by itself prevent insecure code, exposed storage, vulnerable dependencies or excessive permissions from reaching production. Dormant assets and code paths that have not executed may also be less visible to runtime controls.

What the AI-security launch is intended to cover

Sweet says its AI-security capabilities can discover models, agents, LLM servers and AI-enabled services; identify shadow AI; map interactions; and assess AI infrastructure for misconfiguration and over-permissioned access. The company also describes real-time agent-behavior analysis, detection or blocking of prompt-injection attacks, abnormal-activity alerts, disallowed-action blocking and guardrails.

Those functions span several distinct security problems. Buyers should establish which of the following are actually included, how they work, and what remains outside the platform:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
  • Inventory and discovery of models, agents, tools and AI-enabled services.
  • AI infrastructure posture, model and data protection, and identity and authorization for agents.
  • Prompt-injection and indirect-injection defenses, plus authorization of tool calls and external actions.
  • Runtime behavior monitoring, data-loss prevention, logging and incident response.
  • Model provenance, supply-chain controls, red teaming, adversarial testing and governance.

A platform that monitors agent runtime behavior may still leave buyers needing separate controls for model governance, training-data protection, secure development, model-risk management or regulatory compliance.

Why runtime behavior matters for AI agents

An AI agent may interpret untrusted instructions, retrieve outside content, call tools dynamically and use delegated credentials to reach business data. A harmful result can emerge from a chain of individually permitted steps rather than a single obviously malicious request.

For example, an agent might retrieve a document containing malicious instructions, use an authorized API tool and send sensitive data to an inappropriate destination. Defending against that chain requires more than prompt filtering: teams need least-privilege identities, explicit tool-use authorization, data-flow controls, runtime monitoring, investigation records and a safe way to stop or reverse high-impact actions. Sweet’s CEO frames over-permissioned agents and invisible data access as risks that traditional microservice models do not fully capture in the funding-rationale post.

That is a reasonable case for adding runtime context, not evidence that static posture controls are obsolete. Prompt-injection defenses can be bypassed or undermined by malicious retrieved content, unsafe plugins, compromised dependencies, credential theft, data poisoning or excessive permissions. Layered controls remain necessary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

What Sweet says about growth—and what remains unverified

Sweet’s financing announcement reports sixfold ARR growth and a tenfold expansion in enterprise customers over the preceding year, along with multiple Fortune 1000 customers, displacement of incumbent vendors and a newly granted U.S. patent related to LLM-assisted identification of anomalous log sessions. It also cites detection “noise” reduced to 0.04%. These are company-reported figures, not independently verified results in the materials cited here.

The company does not specify the ARR baseline or exact measurement period, what “enterprise-customer expansion” counts, or whether Fortune 1000 references represent pilots or production deployments. It also does not define “noise”: that figure should not be treated as a 0.04% false-positive rate without a denominator, ground-truth method, recall and precision data, and an explanation of how alerts were reviewed. The announcement material cited here does not identify the patent number, filing and grant dates, or claim scope.

Sweet’s homepage also claims inline AI-guardrail enforcement in under 100 milliseconds. The company homepage does not, in the cited material, state the test conditions or whether that figure is a median, average or tail latency. Buyers should request the hardware, model, traffic and workload details behind the metric before using it to assess production impact.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How Sweet fits against established CNAPP platforms

Sweet enters a competitive market in which broader platform vendors also promote cloud, runtime and AI-security capabilities. Product-page descriptions indicate different emphasis, not a verified ranking; buyers should compare the controls and telemetry in their own environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
Platform Published positioning Buying and pricing information in cited material
Sweet Security Runtime-first cloud security, with AI discovery, posture, behavior analysis and guardrails. Sweet runtime CNAPP Demo and risk-assessment calls to action; no public numerical price in the cited material. Sweet homepage
Wiz Agentless cloud-and-AI visibility, security-graph and attack-path analysis, code-to-cloud context and runtime protection. Wiz platform Personalized demo; no public numerical price in the cited page.
Sysdig Secure Cloud, containers, Kubernetes, hosts, serverless, posture, vulnerability management and runtime detection and response. Sysdig CNAPP Quote-based. Its pricing page describes host-based licensing for core environments and event-based licensing for cloud logs. Sysdig pricing
Orca Security Single-SKU positioning across CNAPP, application security, runtime, posture, identity, data, APIs, containers and AI-SPM. Orca pricing discussion Personalized demo rather than public numerical pricing in the cited material. Orca demo

Sweet’s “first unified” label should not be read as proof that competitors lack cloud-and-AI or runtime features. For example, Wiz and Sysdig also market combinations of cloud and runtime security, while Orca describes AI-SPM within a broader platform. The meaningful comparison is control depth and operational fit, not the category name.

What to verify before requesting a proof of value

A demo is most useful when it exercises your own workloads and AI use cases. Ask vendors to show the following, and agree in advance how results will be measured:

  • Environment coverage: Which AWS, Azure and GCP services, Kubernetes distributions, containers, virtual machines, serverless environments and SaaS integrations are supported? Does coverage extend to development and CI/CD as well as production?
  • Sensor compatibility: Sweet promotes eBPF, but confirm supported operating systems and kernel versions, deployment architecture, telemetry retention and performance impact. Test customized or older kernels, managed Kubernetes, Fargate-like environments, Windows workloads, host restrictions and latency-sensitive services. Sweet’s release resources should be checked for current feature availability rather than assuming coverage across every edition or environment.
  • Runtime attribution: Can an event be traced to the process, workload, identity, API and cloud resource involved? How much context is retained for investigation? Does the product detect only, or can it prevent?
  • AI coverage and enforcement: Demonstrate inventory of agents and shadow AI, indirect prompt-injection handling through retrieved documents or websites, tool-call authorization, least-privilege enforcement, data-exfiltration controls, behavior baselines and human approval for high-impact actions.
  • Blocking safety: Test fail-open and fail-closed behavior, emergency bypass, policy rollback, latency and what happens if the security control is unavailable. Inline blocking can stop harmful actions but can also disrupt legitimate automation.
  • Operational integration: Check SIEM, SOAR, ticketing, identity and cloud-native integrations; role-based access, APIs and export; detection-rule customization; policy-as-code; evidence retention; and implementation and tuning needs.
  • Commercial model: Ask whether pricing is based on hosts, workloads, cloud resources, event volume, users, agents, models or requests. Confirm module boundaries, minimum annual commitments, support, professional services and overage fees.
  • Proof-of-value methodology: Define the workloads, test cases, ground truth, alert review process, performance limits and success criteria. Request evidence for detection precision and recall, not just an alert-noise percentage.

Consolidating tools can reduce operational sprawl, but it can also increase dependence on one vendor’s telemetry and roadmap, complicate migrations, and concentrate risk if the platform is misconfigured. Compare breadth against best-of-breed depth using the controls your team actually needs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.